Description
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.
Remediation
References
Related Vulnerabilities
PostgreSQL Other Vulnerability (CVE-2002-1399)
MySQL CVE-2013-2375 Vulnerability (CVE-2013-2375)
LimeSurvey CVE-2008-2570 Vulnerability (CVE-2008-2570)
Internet Information Services Improper Input Validation Vulnerability (CVE-2000-0258)
Undertow Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2023-1108)